iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Three September 2024 security stories exposed different trust failures: a PDF reader flaw with a crash-capable proof of concept, stale WHOIS software querying an expired domain, and a WhatsApp privacy feature that researchers said modified clients could bypass. The evidence was not the same in all three cases: Adobe said it knew of no in-the-wild exploitation, WatchTowr demonstrated control of residual WHOIS traffic, and the WhatsApp bypass and prior exploitation account came from the Zengo research team.
Adobe Reader: a critical flaw, but not a confirmed zero-day attack
What the vulnerability could do
Adobe’s September 10, 2024 security bulletin covered CVE-2024-41869, a use-after-free vulnerability in Acrobat and Reader for Windows and macOS. Adobe rated it critical, assigned it a CVSS 3.1 score of 7.8, and listed arbitrary code execution as a potential impact. NIST’s CVE record says an attacker would need a victim to open a malicious file.
What was known about exploitation
Adobe said it knew of a proof of concept that could make Acrobat and Reader crash, but was not aware of the flaw being exploited in the wild. SecurityWeek’s September 13 roundup characterized the proof of concept encountered by researcher Haifei Li of EXPMON and Check Point Research as not fully working; it was unclear whether it reflected malicious zero-day development or good-faith testing. That evidence supports describing this as a possible or suspected zero-day story, not as a confirmed active attack.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchHistorical patch information
Adobe’s bulletin recommended updating and listed these fixed versions for the relevant products and platforms: Reader DC 24.003.20112 (continuous track), Reader 2024 24.001.30187, and Reader 2020 20.005.30680. These are version numbers from the 2024 bulletin, not current update guidance.
#1 Best Overall
How WatchTowr took control of a legacy .mobi WHOIS domain
Why an expired hostname still mattered
The .mobi WHOIS server hostname had changed from whois.dotmobiregistry.net to whois.nic.mobi, but some older clients continued querying the former address. After that old domain expired, WatchTowr registered it and operated a server that received the leftover WHOIS requests. WatchTowr reported paying $20 to acquire the domain.
What the traffic figures do—and do not—show
WatchTowr reported more than 135,000 systems and more than 2.5 million queries; SecurityWeek relayed those figures in its September 13, 2024 roundup. They describe the residual traffic observed in this incident, not all .mobi traffic, and do not mean that the same number of websites were compromised.
Rank #2
- Create and edit PDFs. Collaborate with ease. E-sign documents and collect signatures. Get everything done in one app, wherever you go.
- Edit text and images without jumping to another app.
- E-sign documents or request e-signatures on any device. Recipients don’t need to log in to e-sign.
- Convert PDFs to editable Microsoft Word, Excel, or PowerPoint documents.
- Share PDFs for collaboration. Commenting features make it easy for reviewers to comment, mark up, and annotate.
Control of the old domain gave its operator the potential to influence responses received by clients still relying on it. WatchTowr described possible downstream risks, including abuse of trust processes connected to TLS certificate validation. The report demonstrates an infrastructure and stale-configuration risk; it does not establish that all .mobi websites were taken over or that certificates for every such site were issued.
WhatsApp View Once: what Zengo said could be bypassed
A privacy setting enforced by clients
In a September 9, 2024 disclosure, Zengo said View Once media could reach linked devices and that the view-once state was a flag clients could change. According to the research team, modified clients or browser extensions could make the media available as ordinary content rather than preserve its view-once restriction. Zengo also said it reported its findings to Meta and learned that others had already exploited a similar bypass before publication. These technical claims and the account of prior exploitation are attributable to Zengo; the sources reviewed for this historical roundup do not independently confirm them through Meta.
Rank #3
What View Once can and cannot promise
Zengo reproduced WhatsApp’s help text describing media that disappears after a recipient opens it once, along with WhatsApp’s warning that someone could photograph or record the displayed media with another device before it disappears. That caveat matters even without a software bypass: View Once may reduce casual retention, but it cannot guarantee confidentiality once another person can see the content.
The reviewed sources do not establish WhatsApp’s present-day remediation or the current behavior of the feature, so this is a report of the September 2024 disclosure rather than a statement about current app status.
Rank #4
Why these three stories are not the same kind of exploit
The Adobe report concerned a document parser flaw that could potentially enable code execution after a malicious file was opened; Adobe’s stated evidence was a proof of concept that could crash the application, with no known in-the-wild exploitation. The .mobi incident concerned control of an expired infrastructure name still queried by old clients, with observed residual traffic and potential downstream trust abuse. The WhatsApp disclosure concerned a feature restriction that Zengo said could be defeated in modified clients, and its claim of earlier exploitation came from that research team.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteThe shared lesson is about where trust is enforced: in software handling a file, in systems depending on an old hostname, or in a client’s interpretation of a privacy flag. The implications and strength of evidence differ, so none should be generalized into a claim that all three were confirmed widespread attacks.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

